
GIAC Penetration Tester (GPEN)
Domain 2Objective 1
Exploitation Fundamentals GPEN Practice Questions (Page 7)
Part of the Exploitation and Post-Exploitation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
7concepts
Questions 31–35
- 31
In the context of a penetration test, what is the primary objective of the exploitation phase?
Select an answer first - 32
What is the primary ethical requirement for a penetration tester before conducting exploitation activities?
Select an answer first - 33
A penetration tester is assessing a network service that is known to be vulnerable to a buffer overflow. The tester wants to gain a shell on the target. Which exploitation technique is most directly applicable?
Select an answer first - 34
A penetration tester is in the post-exploitation phase of an engagement. The tester has gained a foothold on a target system and needs to gather additional information to identify other systems on the network. Which activity is most appropriate for this phase?
Select an answer first - 35
A penetration tester is assessing a legacy web application that concatenates user input directly into an SQL query. The tester wants to demonstrate the impact of the vulnerability without causing damage. Which technique is the most appropriate first step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.